dhi.io/opencost
2, 2-debian, 2-debian13, 2.5, 2.5-debian, 2.5-debian13, 2.5.3, 2.5.3-debian, 2.5.3-debian13
sha256:f44c055f28fec7ed325368eed88252969fcbd86e63ff455a1b7cc11f63fc9732
Manifest digest:sha256:d70eeec346d4260c548d9478de6fe4fd0de2302e724386eb7c87359dbe9a4069
Size
33.29 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/opencost:22. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/opencost:2 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/opencost@sha256:08fc519cd6f806ef288d1b4e1b6e4429508e1af53e9990a852f0f39ac5b04188 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/opencost@sha256:f97eb738b05feafbf3c20090fd7a3eae384405ff079482974d878f9e8ab0fad3 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/opencost@sha256:b73e059335d2f1484ad02eb93943bec6499d66032f67fcbdd94b2342d762d6da |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/opencost@sha256:8161f330a24a89d7947914568f6f65d847bbab272f8b28eeed6c0a4c0194250d |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/opencost@sha256:4dd8a860d5c42bd789fcd45ca65265cec008bfe614b6fead1159aff1786b9144 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/opencost@sha256:c5bb9d44d34808d6b1c78ae0c0131ee57e8460548c4b25dc7683ac44e124d63a |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/opencost@sha256:8fbfe490bc9b426a0dc7e2b472e5147e6e2deee8912e533e3a3034d53f447043 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/opencost@sha256:56987cf9ad3ce7a747fbb4c606a37826c5a682648867010519d7ee5d235d1191 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/opencost@sha256:20391f2be2d3adb5d1b4f7bf8f0b0fc2f644a27bcf8e252948e8339b6247d063 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/opencost@sha256:14158a3abd9f7cbfba5724edee48fd7d40b05f6443f35295ba5999b9672644ff |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/opencost@sha256:0e7b8f9780d24718412f528bfd3cc9679aa6a9c036fec430c6fedce78af02cf5 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/opencost@sha256:83a2eb6288052601fb70f306f68d9600e853ab593d35c108643ed1fae3b45769 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/opencost@sha256:8ca63a728938714802424e74d7ac7432621425a3297f43f6b8d3a3d85d6644e2 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/opencost@sha256:0334bf952c1d9bcce7b84fb897a9d671b5c9cf1da511fc3fdd98c8891784a861 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/opencost@sha256:e3d4616177a6d9523316e6fda766d5156253d4b21ca33c3ec27f483c1b72599d |